BRIEFRansomwarehighP45
Everest ransomware publishes Japanese firm UNIRITA
UNIRITA Inc.
Detected25 September 2026 · 16:09 UTC
The Everest ransomware group listed UNIRITA, a Tokyo-listed IT and infrastructure-software vendor, as a victim on its leak site. Named corporate victims such as mid-size IT vendors matter because they can be supply-chain footholds into their customers. It is a real but lower-priority alert for a LATAM-focused feed.
CategoryRansomware
Severityhigh
Priority score45
Detected25 September 2026 · 16:09 UTC
Ransomware● 52
Ransomware Everest publica al organismo europeo CENELECEverest ransomware published CENELEC, the Brussels-based European Committee for Electrotechnical Standardization, as a victim. Standards and electrotechnical/energy-sector bodies are critical-infrastructure adjacent, so the listing matters for supply-chain and sector awareness. It is outside LATAM, so it ranks below regional alerts.Ransomware● 69
Ransomware BLACKNET-00 contra el municipio de Tel Aviv-YafoThe BLACKNET-00 group claims to have breached the Tel Aviv-Yafo municipality, a government target, and is publishing it as a ransomware victim. A municipal compromise exposes citizen services, internal systems and sensitive records, and the same group is listing multiple victims, signalling an active campaign. Even though it is outside LATAM, government-targeting ransomware from an active crew is worth tracking for pattern awareness.Ransomware● 70
Blacknet-00 publica el robo de datos de SriLankan AirlinesThe Blacknet-00 group claims an official breach of SriLankan Airlines, the national flag carrier, typically meaning exfiltrated passenger and operational data. State-linked airlines hold passport, booking and employee data, making this a high-value leak with identity-theft and DDoS follow-on risk. Airlines and their partners should monitor for leaked customer credentials and extortion pressure.Ransomware● 48
Ransomware LockBit publica a la aseguradora de salud Taspen LifeThe LockBit5 group listed Taspen Life, a health and group insurance provider (listed under Kazakhstan), as a ransomware victim. Healthcare breaches disrupt patient and policyholder services and expose sensitive health and personal data. It lies outside Latin America but is a fresh victim relevant for sector and insurer monitoring.Ransomware● 68
Ransomware Qilin publica a la fabricante española Iberia CompositechQilin ransomware listed Iberia Compositech Manufacturing, a Spanish manufacturer, as a fresh victim on its leak site with no sample data published yet. An active extortion usually gives defenders a short window to contain, assess backups and check whether Ibero-American subsidiaries or shared credentials are exposed. Manufacturing is a frequent supply-chain entry point, so this warrants monitoring.Ransomware● 30
Ransomware Pear publica a Martin Lawrence GalleriesThe 'Pear' ransomware group published Martin Lawrence Galleries, a US art retail chain, as a fresh victim. Retail breaches expose customer data and can disrupt operations, though the extortion impact is lower than in healthcare or finance. Limited relevance to the Latin America region.